VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 362 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-58065

Apache Software Foundation Apache Airflow Git provider, apache-airflow-providers-git

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_host...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-6847

4real ThemisNETPanel

Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated attackers to upload arbitrary PHP files by providing a base64-encoded payload and to execute arbitrary code on the underlying server. This issue has been fixed by a patch released in April 2026.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-61498

VITEC Flamingo

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-60121

VITEC Flamingo

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15584

Red Hat Pen Drive Powered by Red Hat Lightspeed

A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-12257

Mura Software CMS

Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14934

Google Cloud BigQuery, Dataform, Colab Enterprise

A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-61956

hamsalam ووسلام – همگام سازی ووکامرس و باسلام

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-61955

Hannan گرویتی فرم فارسی

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59521

ShapedPlugin LLC Real Testimonials

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-59518

wpWax Directorist

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59516

Room 34 Creative Services, LLC ICS Calendar

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-59515

Sergey AIWU

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57816

FunnelKit Funnel Builder by FunnelKit

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57815

WPMU DEV - Your All-in-One WordPress Platform Forminator

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.

The CVSS severity warrants an early asset and exposure review.